
ABUSE.MOM — COMPÓRTATE O SERÁS EXPUESTO
| Firma | Descripción | Puntos | Gravedad |
|---|---|---|---|
| Danger strong hits: 1 | Rutas de alto riesgo: shells, RCE, exploits | +25 | |
| Danger medium hits: 1 | Riesgo medio: paneles admin, archivos de configuración | +10 | |
| 404 ratio >= 60% | Mayoría de solicitudes devolvieron 404 — enumeración | +25 | |
| POST requests present | Anomalía de comportamiento detectada automáticamente | +8 | |
| Danger strong hits: 2 | Rutas de alto riesgo: shells, RCE, exploits | +50 | |
| Danger medium hits: 2 | Riesgo medio: paneles admin, archivos de configuración | +20 | |
| 404 ratio 40-60% | Mayoría de solicitudes devolvieron 404 — enumeración | +15 |
Solicitudes HTTP reconstruidas de los registros del servidor. Dominios objetivo ocultos por seguridad.
* Typical request patterns for detected signatures. Actual target domains are redacted.
IP 103.194.89.51 está enumerando directorios. Configure fail2ban con jail apache-404 tras 10+ errores 404.
Datos de reconocimiento de red de Shodan. Los puertos abiertos pueden indicar servicios en ejecución, configuraciones incorrectas o superficies de ataque.
| Port | Service | Risk | Description |
|---|---|---|---|
| 311 | Unknown | Low | Service on port 311 |
| 443 | HTTPS | Low | HTTPS web server — encrypted web traffic |
| 444 | Unknown | Low | Service on port 444 |
| 465 | Unknown | Low | Service on port 465 |
| 636 | Unknown | Low | Service on port 636 |
| 1337 | Unknown | Low | Service on port 1337 |
| 1926 | Unknown | Low | Service on port 1926 |
| 2083 | Unknown | Low | Service on port 2083 |
| 2087 | Unknown | Low | Service on port 2087 |
| 2376 | Unknown | Low | Service on port 2376 |
| 3001 | Unknown | Low | Service on port 3001 |
| 3269 | Unknown | Low | Service on port 3269 |
| 3780 | Unknown | Low | Service on port 3780 |
| 3790 | Unknown | Low | Service on port 3790 |
| 4064 | Unknown | Low | Service on port 4064 |
| 4433 | Unknown | Low | Service on port 4433 |
| 4434 | Unknown | Low | Service on port 4434 |
| 4443 | Unknown | Low | Service on port 4443 |
| 4444 | Unknown | Low | Service on port 4444 |
| 4911 | Unknown | Low | Service on port 4911 |
| 5001 | Unknown | Low | Service on port 5001 |
| 5006 | Unknown | Low | Service on port 5006 |
| 5986 | Unknown | Low | Service on port 5986 |
| 6443 | Unknown | Low | Service on port 6443 |
| 6697 | Unknown | Low | Service on port 6697 |
| 7001 | Unknown | Low | Service on port 7001 |
| 7071 | Unknown | Low | Service on port 7071 |
| 7415 | Unknown | Low | Service on port 7415 |
| 7434 | Unknown | Low | Service on port 7434 |
| 7443 | Unknown | Low | Service on port 7443 |
| 7548 | Unknown | Low | Service on port 7548 |
| 8009 | Unknown | Low | Service on port 8009 |
| 8083 | Unknown | Low | Service on port 8083 |
| 8085 | Unknown | Low | Service on port 8085 |
| 8089 | Unknown | Low | Service on port 8089 |
| 8139 | Unknown | Low | Service on port 8139 |
| 8140 | Unknown | Low | Service on port 8140 |
| 8181 | Unknown | Low | Service on port 8181 |
| 8443 | HTTPS-Alt | Low | Service on port 8443 |
| 8834 | Unknown | Low | Service on port 8834 |
| 8880 | Unknown | Low | Service on port 8880 |
| 8883 | Unknown | Low | Service on port 8883 |
| 8889 | Unknown | Low | Service on port 8889 |
| 9000 | Unknown | Low | Service on port 9000 |
| 9001 | Unknown | Low | Service on port 9001 |
| 9002 | Unknown | Low | Service on port 9002 |
| 9091 | Unknown | Low | Service on port 9091 |
| 9095 | Unknown | Low | Service on port 9095 |
| 9398 | Unknown | Low | Service on port 9398 |
| 9443 | Unknown | Low | Service on port 9443 |
| 9898 | Unknown | Low | Service on port 9898 |
| 9943 | Unknown | Low | Service on port 9943 |
| 10000 | Unknown | Low | Service on port 10000 |
| 10134 | Unknown | Low | Service on port 10134 |
| 10250 | Unknown | Low | Service on port 10250 |
| 10443 | Unknown | Low | Service on port 10443 |
| 10909 | Unknown | Low | Service on port 10909 |
| 10911 | Unknown | Low | Service on port 10911 |
| 16993 | Unknown | Low | Service on port 16993 |
| 31337 | Unknown | Low | Service on port 31337 |
| 47990 | Unknown | Low | Service on port 47990 |
| 51235 | Unknown | Low | Service on port 51235 |
| 55443 | Unknown | Low | Service on port 55443 |
| 55553 | Unknown | Low | Service on port 55553 |
Fuente: Shodan InternetDB. Escaneado independientemente de abuse.mom.
Esta IP fue verificada contra las principales listas negras DNS utilizadas por servidores de correo y firewalls.
Verificado: Spamhaus, SpamCop, Barracuda, SORBS, CBL, UCEProtect.
103.194.89.51 has been assigned a threat score of 93/100 (Critical). Con esta calificación, la IP cae en el rango de severidad crítica — entre las direcciones más peligrosas en nuestra base de datos de monitoreo.
The following attack categories were identified:
La dirección IP 103.194.89.51 ha sido rastreada hasta Noida, India, operando en la red de Elyzium Technologies Pvt. Ltd.. Nuestros sistemas de detección de amenazas marcaron esta dirección basándose en patrones de comportamiento malicioso observados. Nuestros sensores capturaron 2 solicitudes maliciosas de esta dirección en un período de 6 días, reflejando una cadencia de ataque sostenida de ~0.3 solicitudes por día. Operando desde una red residencial, esta IP puede representar un gateway doméstico comprometido o dispositivo IoT reclutado en una infraestructura de ataque mayor. La IP exhibe comportamiento de enumeración de directorios, solicitando sistemáticamente rutas inexistentes. Nuestros registros muestran 102 IPs maliciosas originadas desde India, posicionándolo como un contribuyente significativa a la actividad de amenazas global. Una puntuación de 93/100 coloca esta dirección en el nivel más alto de severidad.
This IP is classified as residential, suggesting it may belong to a compromised home device, IoT botnet member, or an infected personal computer. Residential IPs involved in attacks often indicate malware infection without the owner's knowledge.
Path traversal attacks attempt to access files outside the intended directory by manipulating file path references. Attackers use sequences like ../ to reach sensitive system files such as /etc/passwd or application configuration files.
Insecure file upload functionality allows attackers to upload web shells, malware, or scripts that execute on the server. Proper validation must check file content, not just extensions, and uploaded files should be stored outside the web root.